
Rockwell Automation Publication ICSTT-RM446N-EN-P - April 2018
101
AADvance Functional Safety System Implementation
Chapter 4
Remote Fault Reset
The AADvance controller offers the ability to remotely initiate a processor
fault reset or standby join. These operations would normally require use of the
processor Fault Reset button. The remote reset feature is enabled and
configured as part of the application.
Program Testing
Even with a small number of inputs, it is possible to reach a point where the
number of tests becomes unreasonable. Eliminating impossible or unlikely
scenarios should be used to reduce the number of logic path tests that need to
be performed. The selection of what constitutes a scenario that does not
require testing can be performed only after a suitable hazard analysis.
The scenarios should include possible plant conditions, sequences of plant
conditions, and system conditions including partial power conditions, module
removal and fault conditions.
Where it is not possible to define a representative suite of test cases, all
permutations of input conditions, i.e. all possible states on all possible inputs,
shall be exercised. Where the logic includes memory or timing elements,
additional tests shall be defined to exercise all the possible sequences of input
permutations leading to their operation.
Program Testing
Even with a small number of inputs, it is possible to reach a point where the
number of tests becomes unreasonable. Eliminating impossible or unlikely
scenarios should be used to reduce the number of logic path tests that need to
be performed. The selection of what constitutes a scenario that does not
require testing can be performed only after a suitable hazard analysis.
ATTENTION:
Consideration should be given to the affect on system safety of
enabling the remote fault/reset join, as continuous fault resets can mask
permanent fault conditions.
To minimize the affect on system safety, the following precautions should be
taken:
•Do not enable the remote fault reset/join feature unless it is required.
•The application should not set the authentication key variables ("Allow Remote
Fault Reset MSB" and "Allow Remote Fault Reset LSB") to the key value. It must
be the remote client that provides the correct key value.
•The authentication key variables should only be set for the time required to
perform a reset, then cleared.
•The authentication key should not be configured as an easy to guess value, for
example 'hex speak' values such as DEADBEEF should not be used.
Содержание AADvance T9110
Страница 4: ...4 Rockwell Automation Publication ICSTT RM446N EN P April 2018 ...
Страница 10: ...10 Rockwell Automation Publication ICSTT RM446N EN P April 2018 Preface ...
Страница 44: ...44 Rockwell Automation Publication ICSTT RM446N EN P April 2018 Chapter 2 Functional Safety Management ...
Страница 116: ...116 Rockwell Automation Publication ICSTT RM446N EN P April 2018 Chapter 5 Checklists ...